View Single Post
  #5 (permalink)  
Old 2006-07-06
RayPesek RayPesek is offline
Senior Member
 
Join Date: 2006-03-19
Location: Northern Ohio
Posts: 909
Rep Power: 3
RayPesek has an average reputation (10+)
Default Re: what does different Community ID mean?

To expand upon dbedit's response, this error usually is seen when traffic that you thought was going down the VPN in fact is not. It's commonly seen when an implied rule accepts the traffic. Since the implied rule is always before any of your rules and before any VPN rules, it can cause odd quirks like this.

Hopefully you do not really have those DNS implied rules active because they open up your internal network's DNS servers in a manner you probably did not intend. They used to be checked by default in 4.0, and I know they are un-checked in NG by default. BTW, with 4.0, I believe they could be used to touch any server on your internal network simply my using port 53 for something other than DNS.

If you do disable them, make sure you have other DNS rules in place or things are going to break...

Ray
Reply With Quote